Security update for python-Django
This update for python-Django fixes the following security issues: - Prevent Denial-of-service possibility by filling session store. (bsc#937522, CVE-2015-5143) - Prevent Header injection possibility. (bsc#937523, CVE-2015-5144) - A remote denial of service (resource exhaustion) attack against the django session store was fixed in Python Django. This might have allowed remote attackers to exhaust existing web sessions. (bsc#941587, CVE-2015-5963)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Django fixes the following security issues: - Prevent Denial-of-service possibility by filling session store. (bsc#937522, CVE-2015-5143) - Prevent Header injection possibility. (bsc#937523, CVE-2015-5144) - A remote denial of service (resource exhaustion) attack against the django session store was fixed in Python Django. This might have allowed remote attackers to exhaust existing web sessions. (bsc#941587, CVE-2015-5963)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/937522
- https://bugzilla.suse.com/937523
- https://bugzilla.suse.com/941587
- https://www.suse.com/security/cve/CVE-2015-5143
- https://www.suse.com/security/cve/CVE-2015-5144
- https://www.suse.com/security/cve/CVE-2015-5963
- https://www.suse.com/support/update/announcement/2015/suse-su-20151810-1/